| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| phpwcms 1.8.0 RC2.tar.gz | 2015-12-02 | 4.3 MB | |
| phpwcms 1.8.0 RC2.zip | 2015-12-02 | 5.7 MB | |
| README.md | 2015-12-02 | 900 Bytes | |
| Totals: 3 Items | 10.0 MB | 0 | |
This release addresses several security related issues like custom inline PHP, file upload and CSRF protection. It is highly recommend to upgrade outdated installations. The security related issues are relevant only when you have access to the backend. This limits the potential.
Because of the massive changes regarding CSRF protection in the backend and the frontend edit keep an eye on all backend activities. Are all links still working as expected, does forms save information correctly and so on. It is no longer possible to send direct backend links to somebody else.
Fixed in RC2
- CSRF GET parameter missed when redirected after editing news
Added to RC2
- generating alias using parental alias
- alias can contain dot
.
This package is not recommend for production at the moment.
Please report any issue.